CVE-2022-0220: WordPress GDPR & CCPA <1.9.27 - Cross-Site Scripting

CVE-2022-0220: WordPress GDPR & CCPA <1.9.27 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享
CVE-2022-0220: WordPress GDPR & CCPA <1.9.27 - Cross-Site Scripting
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-0220: wordpress GDPR & CCPA <1.9.27 – Cross-Site Scripting

漏洞描述

WordPress GDPR & CCPA plugin before 1.9.27 contains a cross-site scripting vulnerability. The check_privacy_settings AJAX action, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type, and JavaScript code may be executed on a victim's browser.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享